A SOC 2 report is often the thing standing between you and a deal, which is why the wrong consultant is so expensive: they slow you down, miss the gaps your auditor will catch, and leave you paying for a second round. A good SOC 2 consultant gets you audit-ready efficiently and produces evidence a CPA firm will accept. This checklist helps you tell them apart before you sign.
First, understand who does what
A point that trips up first-time buyers: a consultant is not your auditor. SOC 2 reports are issued by a licensed CPA firm that performs the audit. A SOC 2 consultant prepares you for that audit: scoping, gap assessment, control design, policy and evidence work, and remediation. A trustworthy consultant is clear about this line and will not imply they can issue the report themselves.
Per the AICPA Trust Services Criteria, the Security (Common Criteria) category applies to all SOC 2 engagements, with Availability, Processing Integrity, Confidentiality, and Privacy selected based on your service commitments and what customers require.
Not sure how ready your environment is before you engage a consultant?
Run the free self-assessment and get an instant readiness score so your first conversation is grounded in facts.
The criteria that matter
1. SOC 2 specialism, not generic compliance
SOC 2 has its own Trust Services Criteria and evidence expectations. Look for a consultant who does this regularly, not a generalist who treats every framework the same. Ask how many SOC 2 engagements they have guided and through which auditors. A consultant with genuine cybersecurity depth and SOC 2 experience will scope your engagement differently from one who handles SOC 2 alongside dozens of other frameworks.
2. They scope the right Trust Services Criteria
Every SOC 2 covers Security, but Availability, Processing Integrity, Confidentiality, and Privacy are optional and depend on what you do and what customers require. A good consultant helps you include exactly the criteria you need and no more, because scope drives cost and timeline. Over-scoping is one of the most common ways SOC 2 compliance projects blow their budget.
3. Type 1 vs Type 2 guidance
A consultant should help you choose between a SOC 2 Type 1 report (controls designed at a point in time) and a SOC 2 Type 2 report (controls operating effectively over a period). Most enterprise customers eventually want a SOC 2 Type 2, and the right sequencing saves you time and money. Your consultant should be able to articulate why one or the other is right for your timeline and customer requirements.
4. Auditor relationships
Consultants who regularly work with reputable CPA firms can align your evidence to what the auditor expects and smooth the handoff. Ask which audit firms they work with and whether they will support you through fieldwork.
5. A clear path, not just a gap list
Anyone can hand you a list of gaps. A good consultant gives you a prioritized remediation plan, helps author policies and implement controls, and gets you to evidence, not just to a spreadsheet of problems. Evaluate the gap analysis output they have produced for past clients if you can.
6. Tooling that fits, not tooling that locks you in
Many consultants pair with compliance automation platforms to accelerate evidence collection. That can improve your security posture and reduce manual effort, but make sure the recommendation fits your stack and budget rather than locking you into a tool you do not need.
Questions to ask before you engage
- How many SOC 2 engagements have you completed in the last twelve months?
- Which CPA firms do you work with, and can we speak to one as a reference?
- How do you approach scoping? Walk me through a typical scope decision.
- What does your remediation support look like, and what is typically out of scope?
- Do you offer ongoing support through fieldwork, or does your engagement end before the audit?
- How do you help us maintain compliance after the audit is complete?
Red flags to walk away from
A consultant who implies they issue the SOC 2 report, who cannot name the auditors they work with, who scopes every Trust Services Criterion by default to inflate the engagement, or who hands you a gap list with no remediation support, is not the partner you want.
| Criterion | What good looks like | Red flag |
|---|---|---|
| SOC 2 specialism | Regular SOC 2 engagements, named auditor relationships | Generic compliance firm with no SOC 2 track record |
| Criteria scoping | Helps you include only what customers require | Scopes all five criteria by default |
| Type 1 vs Type 2 guidance | Clear rationale matched to your timeline | Vague or recommends Type 2 for every client regardless |
| Auditor relationships | Names CPA firms and supports you through fieldwork | Cannot name auditors or ends engagement before fieldwork |
| Remediation support | Prioritized plan, control help, policy authoring | Hands over a gap list and exits |
| Honesty about the report | Clear that the CPA firm issues the report, not the consultant | Implies they can issue the SOC 2 themselves |
How Onyx helps
Onyx provides SOC 2 readiness consulting: we scope the right Trust Services Criteria for your environment, run a gap assessment, help you design and implement security controls, author the policies and evidence, and prepare you for fieldwork with your chosen CPA firm. We are clear that the audit and report come from a licensed CPA auditor, and we scope to your environment so you are audit-ready without paying for criteria you do not need. Our goal is to get you to a clean first report efficiently.
Getting ready for SOC 2?
Tell us your timeline and what your customers are asking for, and we will scope your readiness on a short call.
See also: SOC 2 readiness assessment, SOC 2 audit cost, and SOC 2 Type 1 vs Type 2. Or take our free security self-assessment before your first conversation.
The bottom line
Choose a SOC 2 consultant who specialises in SOC 2 compliance, scopes the right Trust Services Criteria, guides the Type 1 versus Type 2 decision, works with reputable CPA firm auditors, and gets you all the way to audit-ready evidence, not just a gap list. And make sure they are honest about the line between preparing you and issuing the report.
FAQ
What does a SOC 2 consultant do?
A SOC 2 consultant prepares you for the audit: scoping the Trust Services Criteria, running a gap assessment, designing and implementing controls, authoring policies and evidence, and remediating gaps. They do not issue the report; a licensed CPA firm performs the audit and issues the SOC 2.
Is a SOC 2 consultant the same as the auditor?
No. SOC 2 reports are issued by an independent licensed CPA firm that performs the audit and attests to your controls. A SOC 2 consultant gets you audit-ready. A trustworthy consultant is clear about this distinction and will not imply they can issue the report.
How do I choose a SOC 2 consultant?
Look for genuine SOC 2 specialism, correct scoping of the Trust Services Criteria, guidance on Type 1 versus Type 2, relationships with reputable CPA firm auditors, a real remediation path rather than just a gap analysis, and tooling that fits your stack. Avoid anyone who implies they issue the report.
Should I get a SOC 2 Type 1 or Type 2 first?
A SOC 2 Type 1 reports on control design at a point in time and is faster; a SOC 2 Type 2 reports on controls operating effectively over a period and is what most enterprise customers eventually require. A consultant should help you sequence them to match customer demand and your timeline.
How much does a SOC 2 consultant cost?
It depends on scope: the Trust Services Criteria in scope, your starting maturity, and how much remediation and policy work you need. A consultant who does not evaluate your situation before pricing is a red flag. Get a scoping conversation before assuming a number.
